Showdoc is a documentation and knowledge-base platform whose vulnerability footprint concentrates in a single, focused product. The recurring weakness classes—cross-site scripting, unrestricted file uploads, cross-site request forgery, open redirects, and weak cryptographic randomness—reflect characteristic risks in web-based applications where user input handling, file management, and session management are central to the threat surface. A meaningful share of the vendor's disclosures reach serious severity, consistent with the web application attack surface. Defenders deploying Showdoc instances should prioritize input sanitization, file-upload controls, and CSRF protections as part of application hardening; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Showdoc over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0520CRITICAL An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue | Apr 29, 2025 | 9.4 | 34 | NO | NO |
CVE-2022-0362CRITICAL SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. | Jan 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-36440CRITICAL Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'. | Sep 8, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-0967MEDIUM Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. | Mar 15, 2022 | 5.4 | 31 | NO | YES |
CVE-2021-41745CRITICAL ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. | Oct 22, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-4168HIGH showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | Dec 26, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-4017HIGH showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | Dec 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-3990MEDIUM showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | Dec 1, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-3683MEDIUM showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | Nov 13, 2021 | 6.5 | 23 | NO | NO |
CVE-2022-0951MEDIUM File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. | Mar 15, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Showdoc.
Media articles that mention a CVE ID that affects a product developed by Showdoc — matched by CVE ID, not by vendor name.